Privacy Policy: The short version
Stephanie Green Psychology ABN 62 258 248 418 Last updated: May 2026
I am Stephanie Green, a registered psychologist. This policy explains what I do with your information, whether you are a client, someone who has contacted me, or a visitor to my website.
If you are a client, I hold health information about you. That means your contact details, your referral, my session notes, assessment results and payment records. I collect it so I can work with you safely and meet my legal and professional obligations. I keep it secure, and I keep it for at least seven years after our last contact.
I share your information with your GP or another practitioner only when you have agreed to it, and with Medicare when you claim a rebate. I share it without your agreement only where the law requires it, or where someone's safety is at serious and immediate risk.
If you have only visited my website or joined my email list, I hold your first name and email address, and nothing clinical. You can unsubscribe at any time using the link in any email.
I use a small number of technology providers to run the practice. Some of them store information outside Australia, including in the United States. I choose providers carefully, but I cannot control another country's laws.
I never sell, rent or trade your information.
You can ask to see what I hold about you and ask me to correct it. Email me and I will respond within 30 days.
If you are unhappy with how I have handled your information, tell me first and I will look into it. If you are still unhappy, you can complain to the Office of the Australian Information Commissioner.
The rest of this page sets all of that out in full.
Who this policy covers
This policy applies to clients, people considering becoming clients, people who contact me, people who subscribe to my email list, and visitors to www.stephaniegreenpsychology.com.au.
I am bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. As a health service provider I am covered by the Act regardless of the size of my practice. Where I hold health information about clients in New South Wales, Victoria or the Australian Capital Territory, state and territory health records legislation applies as well. I also work under the confidentiality and record keeping requirements of the Psychology Board of Australia and the Australian Health Practitioner Regulation Agency.
Being anonymous or using a pseudonym
You can browse my website and read anything on it without telling me who you are.
You can also ask a general question by phone or email without giving me your name. If you want to become a client, I need your real name and details, because I cannot provide psychological services safely, keep proper records, or process a Medicare claim without them.
How I collect it
I collect information directly from you in almost every case, through my booking and intake forms, in session, through the forms on my website, and in our correspondence.
Sometimes I receive information about a client from someone else, most often a referring GP, psychiatrist or other practitioner, or a parent or guardian. If I receive information about you from someone else and you would not expect me to have it, I will tell you.
How I collect it
I collect information directly from you in almost every case, through my booking and intake forms, in session, through the forms on my website, and in our correspondence.
Sometimes I receive information about a client from someone else, most often a referring GP, psychiatrist or other practitioner, or a parent or guardian. If I receive information about you from someone else and you would not expect me to have it, I will tell you.
Why I collect it
I collect client health information so that I can provide psychological services safely and competently, process payments and Medicare claims, and meet my legal, professional and insurance obligations to keep adequate records. Confidentiality and its limits are explained to you in full in my consent and intake documents.
I collect contact details from website enquiries so that I can respond to you.
I collect subscriber details so that I can send you the resource you asked for and, after that, occasional articles and information about my services.
I use website analytics to understand which pages people find useful so I can improve the site.
Consent
By giving me your information you agree to me collecting, holding, using and sharing it as this policy describes.
If you are a client, I also talk through confidentiality and its limits with you at the start of our work, and my intake and consent documents set this out in more detail. I will ask you separately before I contact your GP or anyone else about you.
You do not have to give me your information. If you decide not to give me what I need to work with you safely, I will tell you what that means for the services I can provide.
Who I share it with
I do not sell, rent or trade personal information, and I do not share it for anyone else's marketing.
With your agreement, I share information with your GP, psychiatrist, another treating practitioner, or someone else you nominate. Where you claim a Medicare rebate, the details Services Australia needs are sent to them.
I share information without your agreement only in these situations: where the law requires or permits it, where there is a serious and imminent risk to your life, health or safety or someone else's, where records are subpoenaed by a court, or where I am required to make a mandatory report.
I discuss my clinical work in professional supervision. Identifying details are removed wherever possible, and my supervisor is bound by the same confidentiality obligations I am.
I use technology providers to run the practice, and your information passes through their systems as part of normal business. These are my practice management and client records system, my payment processor, my email and calendar provider, my cloud file storage, my email marketing platform and my website platform. Each is bound by its own privacy obligations, and I choose providers with appropriate security.
Information stored outside Australia
Some of those providers store information outside Australia, including in the United States. Your information may sit on servers in another country and be subject to that country's laws.
Before information goes to an overseas provider, I take reasonable steps to satisfy myself that they handle it consistently with the Australian Privacy Principles. I cannot control another country's laws, and I want you to know that rather than discover it later.
If you subscribe to my email list, your first name and email address are held by my email marketing provider outside Australia. If you would prefer your information not to be held overseas, tell me and I will talk through the options with you.
Emails and marketing
If you have given me your email address through my website, I send you articles, resources and occasional information about my services. Every one of those emails identifies me and has a working unsubscribe link. Unsubscribing takes effect straight away, and in any case within five working days. You can also just email me and ask to come off the list.
Being a client of my practice does not put you on my email list, and I never use client information for marketing.
Using my website
You can browse the site without identifying yourself. If you fill in a form, that information is handled as this policy describes.
My website uses cookies, which are small files your browser stores. They help the site work and let me see which pages get visited most. You can turn cookies off in your browser settings, though some parts of the site may not work as well.
How I keep your information safe
Client records are held in a purpose built practice management system, with access restricted to me and protected by a password and multi-factor authentication. Paper records are kept in a locked cabinet. My devices are password protected and encrypted.
I take reasonable steps to protect your information from misuse, loss, unauthorised access, modification and disclosure. No electronic system is completely secure, so I cannot promise absolute security, and I will not pretend otherwise.
Email and text message are not secure. I use them for practical things like appointment times when you have asked me to, and I keep clinical content out of them wherever I can.
If something goes wrong
If a data breach happens that is likely to cause serious harm, I will assess it within 30 days and, where it meets the threshold, tell both you and the Office of the Australian Information Commissioner as soon as I can. This is required by the Notifiable Data Breaches scheme.